API reference
Enterprise sign-in (SSO, SCIM) API
5 operations under /fabric/sso
Last reviewed 2026-10-02
Base URL https://cainstudio.online. Every call carries your key in the X-API-Key header; a free key comes from sign-up, and agent keys from the console. A key only ever sees its own tenant. A call the platform cannot decide is refused, never allowed: timeouts, outages and unknown verdicts do not become ALLOW.
| Method | Path | What it does |
|---|---|---|
| GET | /fabric/sso | This workspace's single sign-on connection |
| PUT | /fabric/sso | Register this workspace's OpenID Connect identity provider |
| DELETE | /fabric/sso | Remove single sign-on (members keep their memberships) |
| POST | /fabric/sso/scim-token | Mint the SCIM provisioning token (shown once) |
| DELETE | /fabric/sso/scim-token | Revoke the SCIM provisioning token |
Try CAIN-42 on your own agents
Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.
Create a free account → · Try the sandbox · See the whole ecosystem